Cybersecurity readiness starts with knowing where you stand.
The InfoPathways CIS Critical Security Controls Readiness Assessment gives executives and business owners a clear picture of how well their organization has implemented the CIS Controls v8. The assessment evaluates key areas including asset management, data protection, access control, vulnerability management, logging, malware defense, network security, incident response, employee training, third-party risk, and security testing.
Section 1 of 10
CIS Critical Security Controls Readiness Assessment
This assessment evaluates your organization's implementation of the CIS Controls v8, a prioritized set of cybersecurity best practices.
You will be asked about your asset management, data protection, access controls, vulnerability management, and incident response capabilities.
Estimated time: 10-15 minutes
Asset Management (CIS 1-2)
1. Does your organization maintain an accurate, up-to-date inventory of all hardware assets including computers, servers, network devices, and mobile devices?
2. Does your organization maintain an accurate inventory that distinguishes between authorized and unauthorized software running on your systems?
Data Protection (CIS 3)
3. Does your organization classify all data based on its sensitivity level (e.g., public, internal, confidential, restricted)?
4. Does your organization encrypt sensitive data both at rest (in storage) and in transit (during transmission)?
5. Does your organization enforce documented data retention and disposal schedules to securely remove data when no longer needed?
Secure Configuration (CIS 4)
6. Has your organization established and documented secure configuration baselines for all system types, and do you maintain them consistently?
7. Does your organization remove or disable default passwords, unnecessary services, and unused software on all systems?
Account Management (CIS 5)
8. Does your organization maintain a complete inventory of all user accounts, service accounts, and administrative accounts?
9. Does your organization enforce strong, unique passwords for all accounts and promptly deactivate accounts when employees leave or change roles?
Access Control Management (CIS 6)
10. Does your organization grant and revoke access based on the principle of least privilege, ensuring users have only the minimum access needed for their role?
11. Does your organization require multi-factor authentication (MFA) for all users accessing applications and systems that are exposed to the internet?
Vulnerability Management (CIS 7)
12. Does your organization have a defined vulnerability management process that includes scanning, identification, and tracking?
13. Does your organization remediate vulnerabilities based on risk assessment, prioritizing critical and high-severity issues?
Logging, Detection & Email Protection (CIS 8-9)
14. Does your organization collect, review, and retain audit logs from all critical systems for security monitoring and incident investigation?
15. Does your organization use fully supported browsers and email clients and keep them updated with the latest security patches?
16. Does your organization deploy DNS filtering and URL/attachment protection to prevent users from accessing malicious content?
Malware Defense & Data Recovery (CIS 10-11)
17. Does your organization deploy and actively maintain anti-malware software on all endpoints with automatic signature updates?
18. Does your organization perform automated backups of critical data and regularly test the backups to ensure data can be recovered?
Network & Incident Management (CIS 12-13, 17)
19. Is your network infrastructure securely managed with documented configurations, and are you using network segmentation to isolate critical systems?
20. Does your organization monitor network traffic for anomalous or suspicious activity and investigate potential security incidents?
21. Does your organization have a documented incident response process with defined roles, responsibilities, and communication procedures?
Training, Third-Party & Testing (CIS 14-18)
22. Does your organization provide regular security awareness and skills training to all employees to build a security-conscious culture?
23. Does your organization maintain an inventory of all service providers and actively assess and manage the risks they introduce?
24. Does your organization follow a secure software development process that includes security testing and code review?
25. Does your organization conduct periodic penetration testing and vulnerability assessments to validate the effectiveness of your security controls?
Almost Done!
Please enter your information below to receive your results via email.
Assessment Complete
Your detailed CIS Controls readiness assessment and remediation roadmap have been sent to . Check your inbox for your full report.